Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,150,778 members, 7,810,028 topics. Date: Friday, 26 April 2024 at 06:59 PM

Hacker Shows How To Hack Any Facebook Page; Earns $16k As Bug Bounty Hacker Show - Phones - Nairaland

Nairaland Forum / Science/Technology / Phones / Hacker Shows How To Hack Any Facebook Page; Earns $16k As Bug Bounty Hacker Show (1599 Views)

KRACK Attack: 41% Of Android Devices Are Easy To Hack / Nigerians Storm Glo Facebook Page With Poor Ratings, Glo Removes Ratings / Nigerians Bad Mouth Injoo Phones On Their Facebook Page ( Pictures) (2) (3) (4)

(1) (Reply) (Go Down)

Hacker Shows How To Hack Any Facebook Page; Earns $16k As Bug Bounty Hacker Show by asifawarley(m): 7:42am On Sep 20, 2016
EVERYONE WANTS TO KNOW HOW TO HACK A FACEBOOK PAGE OR AN ACCOUNT BUT NO ONE WANTS TO DO THE HARD WORK — HERE’S AN INDIAN HACKER WHO FOUND A CRITICAL SECURITY FLAW IN FACEBOOK BUSINESS MANAGER ALLOWING HIM TO HACK ANY FACEBOOK PAGE WITHIN 10 SECONDS.
Arun Sureshkumar, an Indian IT security researcher exposed a critical vulnerability in Facebook business manager allowing attackers to take over any Facebook page – In return Facebook awarded Sureshkumar with 16,000 USD as part of the bug bounty program.

how-to-hack-any-facebook-page-bug-bounty-4
Arun Sureshkumar / Image Source: Facebook

The issue discovered by hacker revolves around Insecure Direct Object Reference, also called IDOR. It refers to when a reference to an internal implementation object, such as a file or database key, is exposed to users without any other access control. In such cases, the attacker can manipulate those references to get access to unauthorized data. In Facebook’s case, IDOR vulnerability in Facebook Business Manager allowed him to take over any Facebook page in less than 10 seconds.
Business Manager actually lets businesses share and control access to their ad accounts, Pages, and other assets on Facebook. Anyone on a business page can see all of the Pages and ad accounts they work on in one place, without sharing login information or being connected to their coworkers on Facebook.
The researcher also mentioned that an attacker could even take over pages like Bill Gates, Narendra Modi , Barack Obama and do whatever kind of damage desired including deleting these pages.
Sureshkumar’s findings:
Sureshkumar made two Facebook business accounts, one as his own and the other for testing purposes. He then added a partner using his own ID and intercepted the request using Burp Suite. After that, he changed the parent business ID with agency ID and asset ID with the page ID he wanted to hack. Once done with changing IDs, the researcher requested manager role on the page.
hacker-shows-how-to-hack-any-facebook-page-earns-16k-as-bug-bounty
In few seconds, Sureshkumar had admin rights on the target page thus allowing him to perform the actions he wanted through the business manager.
Watch how Sureshkumar was able to hack a Facebook page in no time at all:

The security flaw was reported to Facebook on 29th August 2016 and lucky for Sureshkumar, while investigating his report; Facebook found and fixed another issue as well. That made the total bug bounty amount higher than those usually paid for page related flaws. As a consequence, he was paid 16,000 USD on the 16th of September this year.

hacker-shows-how-to-hack-any-facebook-page-earns-16k-as-bug-bounty-2
Email conversation shared by Arun

More technical details are available on Arun SureshKumar’s blog.
For more Facebook Tricks and Update click here

1 Like

Re: Hacker Shows How To Hack Any Facebook Page; Earns $16k As Bug Bounty Hacker Show by Flexherbal(m): 7:45am On Sep 20, 2016
Men with intelligence !
Re: Hacker Shows How To Hack Any Facebook Page; Earns $16k As Bug Bounty Hacker Show by speedyconnect3: 7:51am On Sep 20, 2016
tech guys are the bomb
Re: Hacker Shows How To Hack Any Facebook Page; Earns $16k As Bug Bounty Hacker Show by KvnqPrezo(m): 9:49am On Sep 20, 2016
I believe India die..
Re: Hacker Shows How To Hack Any Facebook Page; Earns $16k As Bug Bounty Hacker Show by Dapsonemmanuel(m): 2:05pm On Sep 20, 2016
This crazy Indians be hacking things since 900bc .. Big ups to them though
Re: Hacker Shows How To Hack Any Facebook Page; Earns $16k As Bug Bounty Hacker Show by kelvinnaira: 6:05pm On Sep 20, 2016
For this kind Economy??

See how people dey waste opportunity... I go talk my mind, i no send wetin anybody think.

If na me, i for just create a blog, pay freelancers to pump some articles, add google adsense and secretly start promotion with those big celebrity pages, Lil Wayne, Football clubs, WWE, NBC etc.. I swear, in just 1month, i would have made more than $100k via display ads and anoda $100k via affiliate.

Call me bad Nigerian, na ur own b that.. I just talk my mind

2 Likes

Re: Hacker Shows How To Hack Any Facebook Page; Earns $16k As Bug Bounty Hacker Show by Nobody: 8:08pm On Sep 20, 2016
ethical hacking also pays...
Re: Hacker Shows How To Hack Any Facebook Page; Earns $16k As Bug Bounty Hacker Show by elvision1(m): 2:18am On Sep 21, 2016
crotonite:
ethical hacking also pays...
but it pays less!!

2 Likes

Re: Hacker Shows How To Hack Any Facebook Page; Earns $16k As Bug Bounty Hacker Show by Nobody: 6:24am On Sep 21, 2016
elvision1:


but it pays less!!
less is always a much better alternative to the more that does not last for a long time. smiley

(1) (Reply)

PES 2017 Official Android Game / You Should Buy Panasonic A3 Pro-specifications Are Great / 10 Ways To Make Your Cell Phone Last Longer.

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 16
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.